Description
The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings.
Published: 2026-09-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Update Plugin
AI Analysis

Impact

The Hoo Companion WordPress plugin version 1.0.2 suffers from an unauthenticated stored cross-site scripting flaw in its theme-settings import function. The code accepts data without authentication or sanitization and stores it as the active theme's settings. When a site visitor loads the page, the malicious script executes in their browser, enabling credential theft, session hijacking, defacement, or other malicious actions. The weakness aligns with CWE-79: Improper Neutralization of Input during Web Page Generation.

Affected Systems

Any WordPress installation that has the Hoo Companion plugin 1.0.2 in use is affected. The flaw is independent of the active theme or WordPress core version; any user who browses the site—including administrators—will execute the injected script.

Risk and Exploitability

The CVSS score of 8.8 categorizes the flaw as high severity. Since no authentication is required and the input is not sanitized, exploitation is straightforward: an attacker simply crafts a request to the import endpoint and publishes a malicious payload. The script resides in the theme settings and will persist until the settings are overwritten or the plugin is at risk. The vulnerability is not currently listed in the CISA KEV catalog and the EPSS score is <1%, but the high severity and lack of controls make it a priority to patch.

Generated by OpenCVE AI on September 15, 2026 at 16:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Hoo Companion plugin to the latest version that addresses the import flaw.
  • If an update is not available, disable the theme-settings import endpoint or remove the associated feature.
  • Add a role check so that only administrators can access the import functionality.
  • Remove any injected scripts from the theme settings to restore normal operation.

Generated by OpenCVE AI on September 15, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated attackers to inject arbitrary web scripts which will execute for anyone viewing the site, including administrators. The same request destroys the site's existing theme settings.
Title Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-14T12:39:24.539Z

Reserved: 2026-09-03T08:38:57.540Z

Link: CVE-2026-85129

cve-icon Vulnrichment

Updated: 2026-09-14T12:36:52.608Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T21:17:02.063

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-85129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')